Jump to content

Recommended Posts

Posted (edited)

Can see a lot of schools affected this year as its an upward trend.  Not sure what happened but I know a lot of schools find it hard or have the budget to give extra money to IT Support to help them to try and stop this becoming regular as with the new DFE regs, Cyber essentials etc. a lot of money is needed to comply to help combat attacks.  As a lot of schools front end users don't see the benefit of updated switches, Internet redundancy, Cloud Back Up etc. and all that is needed behind the scenes to keep a school running and secure.  I can see it will be hard for all schools to cover themselves when front line staff and teaching/learning etc. Isn't "seen" to benefit from the expenditure needed.

 

https://www.coventrytelegraph.net/news/local-news/nuneaton-school-closed-until-at-33176735

Edited by JazzFlute
spelling
  • 2 weeks later...
  • 3 weeks later...
Posted

Does anyone have any updates o rumours on this? Currently reviewing our cyber security stuff and this came to mind.

Interesting to see that there phone lines were out of action which looks like there using something on prem but surely the phone company would have a backup of it?

Posted
2 hours ago, AlphamaleZed said:

Does anyone have any updates o rumours on this? Currently reviewing our cyber security stuff and this came to mind.

Interesting to see that there phone lines were out of action which looks like there using something on prem but surely the phone company would have a backup of it?

I think that when incidents like this occur, there should be national internal communications sent to all schools so they can act on any recommendations that come out of the investigation.

Obviously, this shouldn’t be shared through the press, as doing so could expose weaknesses that other attackers might exploit. But I would expect that, at the very least, the DfE could distribute internal guidance, especially considering how much they already require schools to comply with various regulations.

 

It also looks like not everything is fully operational yet:
https://www.highamlaneschool.co.uk/_site/data/files/users/school communications/letters-2025-26/1BF76121BE5A98E097C7C1921D45EDB8.pdf

 

 

Posted

is there any updates on this ? I tried calling them to ask about this but I couldn't get through to them.

 

I agree that whenever things like that happen there should be some communication to help other schools avoid the same issue.

Posted

Ouch. Yes, don't be calling them, what on earth did you think they'd tell you? You could be a nosey parent, a journalist looking for a story, or even the attacker for all they know so you're not going to get anything other than the existing public lines.

 

If they want to release information, they will do so in their own time & via the proper channels.

 

  • Like 2
Posted (edited)
On 02/02/2026 at 12:34, AlphamaleZed said:

Does anyone have any updates o rumours on this? Currently reviewing our cyber security stuff and this came to mind.

Interesting to see that there phone lines were out of action which looks like there using something on prem but surely the phone company would have a backup of it?

Not uncommon to block all access in and out during a cyber incident.

Edited by Davit2005
  • Like 1
Posted (edited)

Hold your horses people, nothing wrong with trying. recpetion can just say no its no big deal what's the harm ? I've done it before with other schools and had some responses. If i had a cyber incident myself and someone called me from another school to ask for advise I would be happy to help!

Edited by xicor
Posted

I've quickly checked the horses, they're fully saddled up and heading for you.

 

It's really bad form to interrupt when someone's in the middle of a crisis. There's lots wrong with trying - you're saying you believe talking to you is more important than getting their own school running again.

  • Like 2
Posted (edited)
7 minutes ago, jmak said:

I've quickly checked the horses, they're fully saddled up and heading for you.

 

It's really bad form to interrupt when someone's in the middle of a crisis. There's lots wrong with trying - you're saying you believe talking to you is more important than getting their own school running again.


I called their reception and asked if there was an update the conversation lasted 20 seconds, no harm done and nobody's time was wasted. 

 

and their update was some time ago so its not like I called them when they just announced an incident... 

Edited by xicor
Posted (edited)
On 07/01/2026 at 22:51, JazzFlute said:

 a lot of money is needed to comply to help combat attacks.

 

There is a lot of free stuff that can be done but isn't. For example, how many people on here have used CIS hardening on their environment? Very few, a quick search only shows 9 posts. This one is more common, but Ping Castle should be ran weekly. How many people have introduced Active Directory tiering? 

Edited by FN-GM
  • Like 1
Posted

Even dealing with staff constantly asking you if it is OK to log into their computer the minute you arrive on site and have not even began to investigate or 

aware you have a problem is infuriating enough, lol.

 

When ever we have been involved in an incident the strict line is no outside discussion unless goes thru official channel.

  • Like 3

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...